It seems your windows device is not configured to use DH group 2 in phase 1 while the ASA is for all its isakmp policies. You should try to activate it under windows or create a new policy without group 2 on the ASA (less secured)